Preprocessing playbooks are used to automate preparatory operations on newly ingested, normalized activity data (see Configuring Data Ingestion). Preparatory operations commonly include deduplication, data enrichment, triage, and correlation.
On the landing page of the Preprocessing Playbooks module, users can search for existing playbooks or create new ones.
UI Breakdown
Playbook Search Panel
Purpose: Allows users to search, browse, and create custom preprocessing playbook categories.
Key Features:
Search Bar: Provides text-based search functionality for quick access to specific playbooks.
Playbook Categories: Organizes playbooks into predefined categories.
Custom Folders: Enables users to create and organize playbooks into custom folders.
Playbook Count: Displays the number of playbooks available in each category or folder.
Playbook Addition Menu (Top Left Dropdown)
Purpose: Enables users to add new playbooks using various methods.
Key Features:
Manual Builder: Opens an interface for manual creation of playbooks.
AI Builder: Uses AI to assist in generating playbooks.
The life cycle of a preprocessing playbook starts when raw data is ingested from an integration. The data undergoes field mapping, and a D3 event is created following the execution of the preprocessing playbook.